Stripe Webhook Signature & Raw Buffer Verifier
AI editors like Cursor and Claude love writing await req.json() in Next.js webhooks. That small mistake alters whitespace and invalidates cryptographic signatures on every single transaction. Paste your route below to test for the 5 biggest webhook landmines.
route.ts)27 linesWhat Happens If Your Webhook Fails?
When a user purchases your product, Stripe sends an HTTP POST event to your webhook. If your signature verification fails, the user is charged on Stripe, but your database never updates. Your customer is left stranded on a loading screen, sending angry emails asking why their account wasn't unlocked.
2 Launch Blockers Detected
Review the test failures below and apply the 1-click fix prompt.
Your route appears to parse JSON before signature verification with req.json().
Fix: Change to "const body = await req.text();". Stripe requires the exact raw payload string to verify the cryptographic HMAC signature.
Reads "stripe-signature" header from incoming request.
Fix: Verified.
Hardcoded Stripe webhook secret string detected (whsec_...).
Fix: Never hardcode your webhook secret. Load it from process.env.STRIPE_WEBHOOK_SECRET.
constructEvent is safely enclosed in try/catch.
Fix: Verified.
Returns response acknowledging receipt.
Fix: Verified.
Stripe webhooks are just 1 of our 108 launch readiness checks. With the Founder Pass ($15 one-time), we inspect your auth flows, API routes, database policies, and dependencies in minutes.